?
Solved

2003 AD GPO Issues

Posted on 2007-11-14
9
Medium Priority
?
228 Views
Last Modified: 2013-11-21
Hi All,
I need to lock down a TS server running QuickBooks. I created the GPO and applied it to an OU called Secure QuickBooks Servers. Within the GPO I defined the required setting including Loopback Processing. The problem I am having is that I have only the QB server computer object in the OU. I also created 2 test accounts for verification. I also have a group call QuickBooks Users which I use for security filtering on the GPO; I have removed the Authenticated Users group.  The GPO will not apply without me adding the test user accounts to the Secure QuickBooks Servers OU which is not an option given that the Policy will then be applied to the user desktops as well ( I think). Is there a way for me to apply the Secure Terminal Server GPO only to the users logging on to the QuickBooks Server, without affecting the administrator or the users desktop environments?

Thank you in advance!


0
Comment
Question by:kbabbing
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 31

Accepted Solution

by:
Cláudio Rodrigues earned 2000 total points
ID: 20281622
1. On the QuickBooks Server OU you must have the TS (I assume your QuickBooks server) ONLY.
2. The Policy you will create will apply to the QuickBook Users AND to the TS Computer object (your QuickBooks Server).
3. Loopback Processing mode should be enabled and set to replace.

This will do what you want that is to have the policy applied to these users only when they logon to the TS (QuickBooks Server).

Cláudio Rodrigues
Microsoft MVP
Windows Server - Terminal Services
0
 

Author Comment

by:kbabbing
ID: 20282956
The problem I am having is that the GPO only applies when the Users and Computer Object reside in the same OU. If I move the test users out of the OU and leave only the Computer object the GPO does not apply. When I run RSOP through GPMC I get all Successes under Component Status but it does end up listed under the Denied GOPs with a reason of Inaccessible.
0
 
LVL 31

Expert Comment

by:Cláudio Rodrigues
ID: 20283009
On the security you must make sure the policy applies to the Computer object AND to the QuickBooks User group.
Is this how you setup it?

Cláudio Rodrigues
Microsoft MVP
Windows Server - Terminal Services
0
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more

 
LVL 31

Expert Comment

by:Cláudio Rodrigues
ID: 20283021
Read this as well.
http://www.msterminalservices.org/articles/Managing-Terminal-Services-Group-Policy.html

Cláudio Rodrigues
Microsoft MVP
Windows Server - Terminal Services
0
 

Author Comment

by:kbabbing
ID: 20283347
I do have the security set that way.
Computer Object Read\Apply and The QuickBooks Users Group Read\Apply
0
 

Author Comment

by:kbabbing
ID: 20283379
The Computer Object is one OU and the Users are in another OU
0
 
LVL 31

Expert Comment

by:Cláudio Rodrigues
ID: 20283503
And the GPO is created at the OU where the Computers are, correct?

Cláudio Rodrigues
Microsoft MVP
Windows Server - Terminal Services
0
 

Author Comment

by:kbabbing
ID: 20285972
The GPO is applied\linked at the Secure QuickBooks Server OU which when working has the 2 test accounts and the Computer Object within.   When I move the User accounts into a different OU the GPO will not apply. All security filtering has been confirmed per your request.
0
 

Author Comment

by:kbabbing
ID: 20291898
Thank you I have found the problem. I over looked the fact that I did not have the Group in the same OU as the Computer object. Rookie mistake... You were very helpful!
0

Featured Post

How Blockchain Is Impacting Every Industry

Blockchain expert Alex Tapscott talks to Acronis VP Frank Jablonski about this revolutionary technology and how it's making inroads into other industries and facets of everyday life.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question